Техническая информация
- <SYSTEM32>\xcopy.exe ""<LS_APPDATA>\Intrenet Explorer.lnk"" "%WINDIR%\" /y /r
- <SYSTEM32>\xcopy.exe ""<LS_APPDATA>\Intrenet Explorer.lnk"" "%APPDATA%\Microsoft\Internet Explorer\Quick Launch" /s /y /r
- <SYSTEM32>\xcopy.exe ""<LS_APPDATA>\Intrenet Explorer.lnk"" "%ALLUSERSPROFILE%\б╕┐к╩╝б╣▓╦╡е" /y /r
- <SYSTEM32>\xcopy.exe ""<LS_APPDATA>\zhibo.ico"" "%WINDIR%\" /y /r
- <SYSTEM32>\xcopy.exe ""<LS_APPDATA>\╠╘▒ж═°.lnk"" "%APPDATA%\Microsoft\Internet Explorer\Quick Launch" /s /y /r
- <SYSTEM32>\xcopy.exe ""<LS_APPDATA>\taobao.ico"" "%WINDIR%\" /y /r
- <SYSTEM32>\xcopy.exe ""<LS_APPDATA>\ie.ico"" "%WINDIR%\" /y /r
- %WINDIR%\ie.ICO
- %WINDIR%\taobao.ico
- <LS_APPDATA>\zhibo.ICO
- %WINDIR%\zhibo.ICO
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\taobao.hao923.com[1]
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Intrenet Explorer.lnk
- %WINDIR%\Intrenet Explorer.lnk
- <LS_APPDATA>\taobao.ico
- <LS_APPDATA>\ie.ICO
- %TEMP%\~1.bat
- <LS_APPDATA>\Intrenet Explorer.lnk
- <LS_APPDATA>\Ц±ІҐіµ.lnk
- <LS_APPDATA>\889.reg
- <LS_APPDATA>\МФ±¦Нш.lnk
- %TEMP%\~1.bat
- 'ta####.hao923.com.cn':80
- 'localhost':1037
- ta####.hao923.com.cn/?09####
- DNS ASK ta####.hao923.com.cn
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''